Privacy Policy for sPParTAN

Last updated: 7 October 2026

This Privacy Policy explains what personal data sPParTAN ("the App") collects, why, and what rights you have over it. It's written to be short and in plain language — if anything is unclear, contact us using the details below.

1. Who is responsible for your data (the "controller")

Politechnika Łódzka (Lodz University of Technology) ul. Żeromskiego 116, 90-924 Łódź, Poland Contact: adp@dmcs.p.lodz.pl

2. What data we collect and why

This section is specific to each app — see Part 2 for sPParTAN.

3. Legal basis for processing

We only process personal data where we have a lawful basis under Article 6 GDPR — in practice, for a free, no-account app like this, that's almost always one of: - Legitimate interest (Art. 6(1)(f)) — e.g. crash/usage reports used to find and fix bugs. - Consent (Art. 6(1)(a)) — for anything the operating system itself prompts you to allow (e.g. location, Bluetooth), which you can withdraw at any time in your device's Settings.

We do not process any data for advertising or profiling.

4. Who we share data with

We only share data with the minimum third parties necessary to run the App's features (listed per-app in Part 2). We do not sell personal data, and we do not use third-party advertising or analytics SDKs. Every service that receives a request from the App (see Part 2) also sees the IP address of your device, which is personal data under the GDPR; we do not receive or store those addresses ourselves.

5. International data transfers

Where a third-party service we use is based outside the EU/EEA (e.g. Apple, headquartered in the US), that transfer is covered by that provider's own GDPR-compliance mechanism (e.g. Apple's Data Processing Agreement and Standard Contractual Clauses). We don't operate our own servers outside the EU/EEA.

6. How long we keep data

7. Your rights

Under GDPR you have the right to: - Access the personal data we hold about you - Correct inaccurate data - Request erasure ("right to be forgotten") - Restrict or object to processing - Data portability - Withdraw consent at any time (e.g. by revoking a permission in your device Settings) - Lodge a complaint with your national supervisory authority — in Poland, the Urząd Ochrony Danych Osobowych (UODO), uodo.gov.pl

To exercise any of these, contact us at adp@dmcs.p.lodz.pl. Since most data processed by this App never reaches us at all (it stays on your device), there is often nothing for us to access, correct, or erase on our end — your device's own Settings app controls most of these in practice.

8. Children

This App is not directed at children and we do not knowingly collect personal data from children.

9. Changes to this policy

We'll update the "Last updated" date above whenever this policy changes, and post the new version at the same URL.


Part 2 — sPParTAN annex

App: sPParTAN 2.0.x, iOS (bundle pl.lodz.p.dmcs.sppartan.app). Heats a Spartan thermal suit and mirrors status on a Garmin fenix 5 Plus watch. Distributed to testers by email via TestFlight (external testing).

What sPParTAN collects:

Data Purpose Shared with Leaves your device?
Location (GPS, only while the app is in use — iOS "When In Use" permission, never "Always") Weather + UV for the thermal model and the weather panel Sent as lat/long to 6 decimal places, roughly every 10 min while the app runs, to Open-Meteo (api.open-meteo.com) Yes
Location, reverse-geocoded to a place name Showing a readable place name in the weather panel Apple's geocoding service (the phone's operating system sends the coordinates to Apple's servers) — not our server Yes, to Apple, sent by the operating system
Location, as a map tile of about 1 km across around your position (zoom level 15; tile numbers, not exact coordinates) Rendering the terrain map panel ArcGIS World Topo Map (Esri) tile server Yes — a map tile of about 1 km around your position, not exact coordinates
Bluetooth: suit sensor data (body temperature, humidity, external temperature, heater output level) Core function — running and displaying the thermal model 100% local — stays between phone and suit, nothing sent to any server (we run none) No
Bluetooth: Garmin watch data, via Garmin Connect / Connect IQ Mirroring temperatures, heater level and status on the watch 100% local, except the watch link itself runs through Garmin Connect on the phone, under Garmin's own terms No, to us — the Garmin Connect hop is Garmin's own, not ours
Crash logs, install/session counts, tester feedback Apple's own TestFlight functionality, not something we collect ourselves Apple — with the tester's own consent via iOS Settings Yes, directly to Apple

Location accuracy, precisely: the app's code requests "Medium" accuracy (roughly a 100–500m class, not GPS-tight), but iOS itself always lets the user grant either Precise or Approximate location independent of what the app asks for — so treat this as "location that may be precise," not guaranteed coarse. Coordinates are sent to Open-Meteo at 6 decimal places regardless of the underlying accuracy class.

Stored only on the device, never uploaded by the app itself: paired suit ID, paired watch ID, settings (theme, language, automation toggles), the learned thermal model state, and a short in-memory sensor history used for on-screen charts (not persisted to disk).

What sPParTAN does not do (this version): - No user account, no login. - No advertising, no tracking. - No third-party analytics or crash-reporting SDK of our own — the only crash/usage data collected is Apple's own TestFlight mechanism, described above.

Planned for a future version (not in this build): self-hosted usage and error monitoring. This policy is written so that a short update (adding a row to the table above) covers it when it ships — it isn't collected yet.